1,156 karma · joined April 12, 2017
The "hack" wouldn't be necessary, or can be done natively in many modern systems.
Indeed. This resonated with me.
Quite a few similarities between parenting and training people.
Sometimes you have to let them suffer a bit, suffering consequences so that they can learn, and sometimes you have to keep them from hurting themselves too much.
You also grow with them. Learning together from different perspectives.
After some time together, you see how your actions, not your words, shape their actions, even some unintentional or unconscious ones.
Are you implying there's automated SIM swap attacks in the wild ? Or, maybe you are saying SMS can be phished ? I do agree SMS 2nd factor can be phished, but if phishing is the attack, password leaks is irrelevant since, you usually phish both passwords and SMS 2nd factor together, so password leaks don't make any difference.
https://theintercept.com/2024/03/25/elon-musk-x-dataminr-sur...
And an important missing part:
> companies like Dataminr continuously monitor public activity on social media and other internet platforms.
This requirement brings a very difficult mix of challenges around security, privacy, regulatory compliance and business priorities.
As a toy / personal project it could work, but realistically this is unlikely to ever materialize in a way that you imagine.
Not all accounts need the same level of security or protection. SMS 2FA can be a very reasonable option depending on the accounts. No law can make that kind of a decision in a reasonable way. So the law has to be toothless (if it leaves too much leeway) or it will remove a valid option from people.
The usability and the availability of other 2FA are not on par with SMS. The gap is not trivial as the author makes it sound like. Account recovery problem is a very difficult one to fix cleanly for all types of accounts. SMS is still a useful option.
Sim swap attack is multiple orders of magnitude more difficult than credential stuffing. It's not close to the most important attack vector for majority of people. It certainly is not worth legislating a solution for specifically. There are reasonable practical solutions for people who want protection against SMS as 2fa from sim hijacking - e.g. many cell phone providers support 2fa or pin to protect it from the sim attack in most scenarios. It's a much cheaper solution for the society than banning SMS 2fa.
You have a fundamental misunderstanding of why captcha exists. If the attacker has to deploy a multimodal LLM to solve captcha, the service provider using captcha has already effectively achieved its goal - since the goal is to raise the cost (in terms of any combination of complexity, computing power, and dollar amount) of sending bulk traffic and ultimately to reduce, not eliminate, the overall attack rate. 0 bulk traffic is never the goal.
https://www.pfizer.com/news/articles/why_and_how_music_moves...
Given how profound the impact seems to be, I would be very surprised if there's no biological component to the correlation between the occupations and the music - but almost certainly the cultural aspect would also play a major role.
https://www.washingtonpost.com/business/2023/03/10/noncompet...
shows the overall home ownership has been going up since 2016, currently around 66% though still lower than peak 69% in 2014, but higher than 63% in 1965.
That said, it's often easy things that get the most benefit and we are collectively a long way away from getting the basic security things done properly across the board.
The number of users on the internet went 5x from 2005 to now.
https://www.zippia.com/advice/online-shopping-statistics/
E-commerce volume went similarly steep and steady in increase.
https://siteefy.com/how-many-websites-are-there/
Number of active websites went up similarly.
https://en.m.wikipedia.org/wiki/Wikipedia:Size_of_Wikipedia#...
Wikipedia number of articles exploded.
> Free. Open-source. For users by users. No donations sought.
> If you ever want to contribute something, think about the people working hard to maintain the filter lists you are using, which are available to use by all for free.
https://fortune.com/2017/10/31/trump-tax-reform-apple-multin...
There are other possible criticisms on corporate tax and Apple, but this isn't a valid one.
It was superior in almost every way. All other browsers had to play the catch-up for a while - especially the performance.
Accountable is interesting - they are as accountable as any other company, and if anything, both are under much closer scrutiny than anyone else, and have bigger reputational risks than anyone else.
> If you choose to use the Workspace extensions, your content from Gmail, Docs and Drive is not seen by human reviewers, used by Bard to show you ads or used to train the Bard model.
is the article. The title is already misleading - Google doesn't support passwordless account, and there is no way to get a passkey only account. So factually incorrect title. Anyway, read that and contrast that with:
https://arstechnica.com/information-technology/2023/05/passw...